Originally posted by Anand Nagloor: How does the role mapping work in the weblogic.xml file?? How do I add the groups created from the console to the weblogic.xml or the web.xml file???

When you add a role mapping in weblogc.xml, you list the principals. These can be either user names or group names that you have defined in the console. For example, look at the example at the bottom of this page:http://e-docs.bea.com/wls/docs61/webapp/security.html From that page, you have weblogic.xml with: <security-role-assignment> <role-name>mgr</role-name> <principal-name>al</principal-name> <principal-name>george</principal-name> <principal-name>ralph</principal-name> </security-role-ref> That maps the role-name "mgr" from the web.xml to the principals al, george, and ralph (which seem to be user names - I suggest using group names here, it is easier to manage). If you do not have a role mapping in weblogic.xml, the default mapping is that the role name is used as the principal name.